We are very pleased about your interest in our company. Data protection has a very high priority for the management of F.H. Papenmeier GmbH & Co. KG. Use of the F.H. Papenmeier GmbH & Co. KG is basically possible without providing any personal data. However, if a data subject wishes to use our company's special services through our website, personal data processing may be required. If the processing of personal data is required and there is no legal basis for such processing, we generally seek the consent of the data subject.
The F.H. Papenmeier GmbH & Co. KG, as controller, has implemented numerous technical and organizational measures to ensure the most complete protection possible for personal data processed via this website. Nevertheless, Internet-based data transmissions can in principle have security gaps so that absolute protection can not be guaranteed. For this reason, every person concerned is free to submit personal data to us by alternative means, for example by telephone.
We comply with legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the different likelihood and severity of the risk to the rights and freedoms of natural persons, appropriate technical and organizational Measures to ensure a level of protection appropriate to the risk.
Measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical access to the data, as well as their access, input, disclosure, availability and segregation. In addition, we have established procedures to ensure the enjoyment of data subject rights, the erasure of data and the response to data threats. Furthermore, we consider the protection of personal data already in the development or selection of hardware, software and procedures, according to the principle of data protection through technology design and privacy-friendly default settings.
Personal data means any information relating to an identified or identifiable natural person (hereinafter the "data subject"). A natural person is considered to be identifiable who, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special features, expresses the physical, physiological, genetic, mental, economic, cultural or social identity of this natural person can be identified.
Affected person is any identified or identifiable natural person whose personal data is processed by the controller.
Processing means any process or series of operations related to personal data, such as collecting, capturing, organizing, organizing, storing, adapting or modifying, reading out, querying, using, with or without the aid of automated procedures; disclosure through submission, dissemination or any other form of provision, reconciliation or association, restriction, erasure or destruction.
Restriction of processing
Restriction of the processing is the marking of stored personal data with the aim to limit their future processing.
Profiling is any type of automated processing of personal data that involves the use of such personal information to evaluate certain personal aspects relating to a natural person, in particular aspects relating to job performance, economic situation, health, personal To analyze or predict preferences, interests, reliability, behavior, whereabouts, or relocation of that natural person.
Pseudonymisation is the processing of personal data in such a way that personal data can no longer be attributed to a specific data subject without the need for additional information, provided that such additional information is kept separate and subject to technical and organizational measures to ensure that the personal data not assigned to an identified or identifiable natural person.
Responsible or data controller
The controller or controller is the natural or legal person, public authority, body or body that, alone or in concert with others, decides on the purposes and means of processing personal data. Where the purposes and means of such processing are determined by Union law or the law of the Member States, the controller or the specific criteria for his designation may be provided for under Union or national law.
A processor is a natural or legal person, public authority, body or body that processes personal data on behalf of the controller.
Recipient is a natural or legal person, agency, agency or other entity to whom Personal Data is disclosed, whether or not it is a third party. However, authorities which may receive personal data under Union or national law in connection with a particular mission are not considered to be beneficiaries.
Third person is a natural or legal person, public authority, body or body other than the data subject, the controller, the processor and the persons authorized under the direct responsibility of the controller or processor to process the personal data.
Consent is any expression of will voluntarily and unambiguously given by the data subject in the form of a statement or other unambiguous confirmatory act expressing to the data subject that they consent to the processing of the personal data concerning them is.
Name and address of the controller
The person responsible within the meaning of the General Data Protection Regulation, other data protection laws in the Member States of the European Union and other provisions with a data protection character is:
F.H. Papenmeier GmbH & Co. KG
Name and address of the data protection officer:
The data protection officer of the controller is:
Herr Karsten Sauer
F.H. Papenmeier GmbH & Co. KG
Any data subject can contact our data protection officer at any time with any questions or suggestions regarding data protection.
Rights of the data subject
Right to confirmation
Each data subject has the right, as granted by the European Directive and Regulatory Authority, to require the controller to confirm whether personal data relating to him / her are being processed. If an affected person wishes to exercise this right of confirmation, they can contact an employee of the controller at any time.
Right to information
Any person affected by the processing of personal data shall have the right granted by the European legislature and the legislature at any time to obtain free information from the controller on the personal data stored about him and a copy of that information. In addition, the European legislator and regulator has provided the data subject with the following information:
- the processing purposes
- the categories of personal data being processed
- the recipients or categories of recipients to whom the personal data have been disclosed or are still being disclosed, in particular to recipients in third countries or to international organizations
- if possible, the planned duration for which the personal data will be stored or, if that is not possible, the criteria for determining that duration
- the existence of a right to rectification or erasure of the personal data concerning them, or to the limitation of the processing by the controller or a right to object to such processing
- the existence of a right of appeal to a supervisory authority
- if the personal data are not collected from the data subject: All available information about the origin of the data
- the existence of automated decision-making including profiling in accordance with Article 22 (1) and (4) of the GDPR and - at least in these cases - meaningful information on
- the logic involved, and the scope and intended impact of such processing on the data subject
Furthermore, the data subject has a right of access as to whether personal data has been transmitted to a third country or to an international organization. If this is the case, then the data subject has the right to obtain information about the appropriate guarantees in connection with the transfer.
If a data subject wishes to avail himself of this right to information, he may, at any time, contact an employee of the controller.
Right to rectification
Any person affected by the processing of personal data has the right granted by the European legislator to demand the immediate correction of inaccurate personal data concerning him. Furthermore, the data subject has the right to request the completion of incomplete personal data, including by means of a supplementary declaration, taking into account the purposes of the processing.
If an affected person wishes to exercise this right of rectification, they may, at any time, contact an employee of the controller.
Right to cancellation (right to be forgotten)
Any person affected by the processing of personal data shall have the right granted by the European Directives and Regulators to require the controller to immediately delete the personal data concerning him, provided that one of the following reasons is satisfied and the processing is not required:
- The personal data has been collected for such purposes or otherwise processed for which they are no longer necessary.
- The person concerned revokes the consent on which the processing was based on Article 6 (1) (a) of the GDPR or Article 9 (2) (a) of the GDPR and lacks any other legal basis for the processing.
- According to Art. 21 (1) GDPR, the data subject objects to the processing and there are no legitimate reasons for the processing, or the data subject objects according to Art. 21 (2) GDPR Processing.
- The personal data was processed unlawfully.
- The deletion of personal data is necessary to fulfill a legal obligation under Union or national law, to which the controller is subject.
- The personal data were collected in relation to information society services offered in accordance with Art. 8 para. 1 GDPR.
If any of the above applies, and a data subject deletes personal data collected by F.H. Papenmeier GmbH & Co. KG, may at any time contact an employee of the controller. The employee of F.H. Papenmeier GmbH & Co. KG will arrange for the extinguishing request to be fulfilled without delay.
Did the personal data of the F.H. Papenmeier GmbH & Co. KG has been made public and if our company is responsible for deleting personal data in accordance with Art. 17 para. 1 GDPR, then F.H. Papenmeier GmbH & Co. KG, taking into account the available technology and implementation costs, shall take appropriate measures, including technical ones, to inform other data controllers processing the published personal data that the data subject is affected by these other data Data Controller has requested the deletion of all links to such personal data or of copies or replications of such personal data, as far as the processing is not required. The employee of F.H. Papenmeier GmbH & Co. KG will arrange the necessary in individual cases.
Right to restriction of processing
Any person affected by the processing of personal data has the right granted by the European directive and regulatory authority to require the controller to restrict the processing if one of the following conditions applies:
- The accuracy of the personal data is contested by the data subject for a period of time that enables the person responsible to verify the accuracy of the personal data.
- The processing is unlawful, the data subject refuses to delete the personal data and instead requests the restriction of the use of personal data.
- The controller no longer needs the personal data for processing purposes, but the data subject needs them to assert, exercise or defend legal claims.
- The person concerned has objection to the processing acc. Art. 21 para. 1 GDPR and it is not yet clear whether the legitimate reasons of the person responsible outweigh those of the person concerned.
If one of the above conditions is met and an affected person has restricted the personal data held by the F.H. Papenmeier GmbH & Co. KG, may at any time contact an employee of the controller. The employee of F.H. Papenmeier GmbH & Co. KG will initiate the restriction of the processing.
Right to data portability
Any person affected by the processing of personal data shall have the right granted by the European Directive and Regulatory Authority to receive the personal data concerning him / her provided to a controller by the data subject in a structured, common and machine-readable format. It also has the right to transmit this data to another person without hindrance by the controller to whom the personal data was provided, provided that the processing is based on the consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) Subparagraph (a) of the GDPR or on a contract pursuant to Article 6 (1) (b) of the GDPR and processing by means of automated procedures, unless the processing is necessary for the performance of a public-interest or public-authority task; which has been transferred to the person responsible.
Furthermore, in exercising their right to data portability under Article 20 (1) of the GDPR, the data subject has the right to obtain that the personal data are transmitted directly from one controller to another, insofar as this is technically feasible and if not so the rights and freedoms of others are impaired.
To assert the right to data portability, the data subject may at any time contact an employee of F.H. Papenmeier GmbH & Co. KG contact.
Right to objection
Any person concerned by the processing of personal data shall have the right conferred by the European directive and regulatory authority at any time, for reasons arising from its particular situation, against the processing of personal data relating to it pursuant to Article 6 (1) (e) or f GDPR takes an objection. This also applies to profiling based on these provisions.
The F.H. Papenmeier GmbH & Co. KG no longer processes the personal data in the event of an objection, unless we can prove compelling legitimate reasons for the processing that outweigh the interests, rights and freedoms of the data subject or the processing serves the purpose Assertion, exercise or defense of legal claims.
The F.H. Papenmeier GmbH & Co. KG personal data in order to operate direct mail, the data subject has the right to object at any time to the processing of personal data for the purpose of such advertising. This also applies to the profiling, as far as it is associated with such direct mail. If the data subject objects to F.H. Papenmeier GmbH & Co. KG processing for direct marketing purposes, the F.H. Papenmeier GmbH & Co. KG no longer process the personal data for these purposes.
In addition, the data subject has the right, for reasons arising from his or her particular situation, against the processing of personal data relating to him, which is the responsibility of F.H. Papenmeier GmbH & Co. KG for scientific or historical research purposes or for statistical purposes pursuant to Art. 89 (1) GDPR, to object, unless such processing is necessary to fulfill a task of public interest.
In order to exercise the right of opposition, the person concerned may directly contact any employee of F.H. Papenmeier GmbH & Co. KG or another employee. The data subject is also free, in the context of the use of information society services, notwithstanding Directive 2002/58 / EC, to exercise his right of opposition by means of automated procedures using technical specifications.
Automated decisions in individual cases including profiling
Any person concerned with the processing of personal data shall have the right granted by the European directive and regulatory authority not to be subject to a decision based solely on automated processing, including profiling, which has a legal effect on it or, in a similar manner, significantly affects it; unless the decision (1) is necessary for the conclusion or performance of a contract between the data subject and the controller, or (2) permitted by Union or Member State legislation to which the controller is subject, and that legislation provides for appropriate measures to safeguard the rights and freedoms and the legitimate interests of the data subject; or (3) with the express consent of the data subject.
If the decision (1) is required for the conclusion or performance of a contract between the person concerned and the person responsible or (2) it takes place with the express consent of the person concerned, F.H. Papenmeier GmbH & Co. KG appropriate measures to safeguard the rights and freedoms as well as the legitimate interests of the data subject, including at least the right to obtain the intervention of a person by the person responsible, to express his own point of view and to contest the decision belongs.
If the data subject wishes to rely on automated decision-making rights, they may, at any time, contact an employee of the controller.
Right to revoke a data protection consent
Any person affected by the processing of personal data has the right, granted by the European directive and regulatory authority, to revoke consent to the processing of personal data at any time.
If the data subject wishes to assert their right to withdraw consent, they may, at any time, contact an employee of the controller.
Transfers to third countries
If we process data in a third country (ie outside the European Union (EU), the European Economic Area (EEA) or the Swiss Confederation) or in the context of the use of third party services or disclosure, or transfer of data to other persons or companies This will only happen if it is to fulfill our (pre) contractual obligations, on the basis of your consent, on the basis of a legal obligation or on the basis of our legitimate interests. Subject to express consent or contractually required transmission, we process or disclose the data only in third countries with a recognized level of privacy, including those certified under the Privacy Shield, or on the basis of specific warranties such as: contractual obligation by so-called standard protection clauses of the European Commission, the existence of certifications or binding internal data protection regulations (Art. 44 to 49 GDPR, information page of the European Commission).
The data subject can prevent the setting of cookies through our website at any time by means of a corresponding setting of the Internet browser used and thus permanently contradict the setting of cookies. Furthermore, already set cookies can be deleted at any time via an internet browser or other software programs. This is possible in all common internet browsers. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our website may be fully usable.
Collection of general data and information
The website of F.H. Papenmeier GmbH & Co. KG collects a series of general data and information with each access to the website by an affected person or an automated system. This general data and information is stored in the log files of the server. Can be recorded the
- used browser types and versions,
- the operating system used by the accessing system,
- the website from which an accessing system comes to our website (so-called referrer),
- the sub-web pages, which are accessed via an accessing system on our website,
- the date and time of access to the website,
- an internet protocol address (IP address),
- the internet service provider of the accessing system and
- other similar data and information used in the case of attacks on our information technology systems.
In using this general data and information, F.H. Papenmeier GmbH & Co. KG no conclusions on the affected person. Rather, this information is needed to
- to deliver the contents of our website correctly,
- to optimize the content of our website as well as the advertising for it,
- to ensure the permanent functioning of our information technology systems and the technology of our website as well
- to provide law enforcement with the necessary information for prosecution in case of a cyberattack. This anonymously collected data and information is provided by the F.H. On the one hand, Papenmeier GmbH & Co. KG was statistically and further evaluated with the aim of increasing data protection and data security in our company in order to ultimately ensure an optimal level of protection for the personal data processed by us. The anonymous data of the server log files are stored separately from all personal data provided by an affected person.
Registration on our website
The data subject has the possibility of registering on the website of the controller, providing personal data. The personal data to be sent to the controller is derived from the respective input mask used for the registration. The personal data entered by the data subject shall be collected and stored solely for internal use by the controller and for his own purposes. The controller may arrange for the transfer to one or more processors, such as a parcel service, who also uses the personal data only for internal use attributable to the controller.
By registering on the website of the controller, the IP address assigned by the Internet service provider (ISP) of the data subject, the date and time of registration are also stored. The storage of this data takes place against the background that only so the misuse of our services can be prevented, and this data if necessary to clarify committed offenses. In this respect, the storage of this data is required to secure the controller. A disclosure of this data to third parties is not, as long as there is no legal obligation to disclose or the disclosure of law enforcement serves.
By registering the data subject voluntarily providing personal data, the data controller serves to provide the data subject with content or services that, due to the nature of the case, can only be offered to registered users. Registered persons are free to modify the personal data given at registration at any time or to delete it completely from the database of the data controller.
The controller shall, at any time upon request, provide information to each data subject as to which personal data about the data subject is stored. In addition, the data controller corrects or deletes personal data at the request or reference of the data subject, insofar as this does not conflict with any statutory retention requirements. All data subjects of the controller are available to the data subject as a contact person in this context.
Contact via the website
The website of F.H. Due to legal regulations, Papenmeier GmbH & Co. KG contains information that enables fast electronic contact to our company as well as direct communication with us, which also includes a general address of the so-called electronic mail (e-mail address). If an affected person contacts the data controller by e-mail or through a contact form, the personal data provided by the data subject will be automatically saved. Such personal information provided on a voluntary basis by a data subject to the controller is stored for the purposes of processing or contacting the data subject. There is no disclosure of this personal data to third parties.
Routine deletion and blocking of personal data
The controller processes and stores personal data of the data subject only for the period necessary to achieve the purpose of the storage or, if so required by the European directives and regulations or any other legislator in laws or regulations, that of the controller subject to was provided.
If the storage purpose is omitted or if a storage period prescribed by the European directives and regulations or any other relevant legislature expires, the personal data will be routinely blocked or deleted in accordance with the statutory provisions.
Deletion of data
The data processed by us will be deleted or restricted in accordance with legal requirements. Unless explicitly stated in this privacy statement, the data stored by us will be deleted as soon as they are no longer necessary for their intended purpose and the deletion does not conflict with any statutory storage requirements.
Unless the data is deleted because it is required for other and legally permitted purposes, its processing will be restricted. That the data is blocked and not processed for other purposes. This applies, for example for data that must be kept for commercial or tax reasons.
We process the data of our contractual partners and interested parties as well as other clients, customers, clients, clients or contractual partners (uniformly referred to as "contractual partners") in accordance with Art. 6 para. 1 lit. b. DSGVO in order to provide them with our contractual or pre-contractual services. The data processed, the nature, scope and purpose and necessity of their processing are determined by the underlying contractual relationship.
The processed data includes the master data of our contractual partners (eg names and addresses), contact data (eg e-mail addresses and telephone numbers) as well as contract data (eg services used, contract contents, contractual communication, names of contact persons) and payment data (eg bank details, payment history ).
In principle, we do not process special categories of personal data, unless these components are the subject of a commissioned or contractual processing.
We process data that are necessary for the establishment and fulfillment of the contractual services and point out the necessity of their information, if this is not evident for the contractual partners. Disclosure to external persons or companies will only be made if required by a contract. When processing the data provided to us within the framework of an order, we act in accordance with the instructions of the client as well as with the legal requirements.
As part of the use of our online services, we can save the IP address and the time of the respective user action. The storage is based on our legitimate interests, as well as the interests of the user in the protection against misuse and other unauthorized use. A transfer of this data to third parties is not, unless it is to pursue our claims acc. Art. 6 para. 1 lit. f. DSGVO required or there is a legal obligation gem. Art. 6 para. 1 lit. c. DSGVO.
The data is deleted if the data is no longer required for the fulfillment of contractual or legal duties of care and for handling any warranty and comparable obligations, whereby the necessity of keeping the data is reviewed every three years; otherwise the statutory storage obligations apply.
Administration, financial accounting, office organization, contact management
We process data in the context of administrative tasks and organization of our business, financial accounting and compliance with legal obligations, such as archiving. In doing so, we process the same data that we process in the course of rendering our contractual services. The processing principles are Art. 6 para. 1 lit. c. DSGVO, Art. 6 para. 1 lit. f. DSGVO. The processing affects customers, prospects, business partners and website visitors. The purpose and interest in processing lies in administration, financial accounting, office organization, data archiving, tasks that serve to maintain our business, perform our duties and provide our services. The deletion of the data with regard to contractual services and contractual communication corresponds to the information provided in these processing activities.
We disclose or transmit data to the financial services, consultants such as tax accountants or auditors, and other fee agents and payment service providers.
Furthermore, based on our business interests, we store information about suppliers, promoters and other business partners, e.g. for later contact. We generally store this majority of company-related data permanently.
Business analysis and market research
In order to operate our business economically, to be able to recognize market tendencies, wishes of the contractors and users, we analyze the data available to us for business transactions, contracts, inquiries, etc. We process stock data, communication data, contract data, payment data, usage data, metadata on the basis of Art 6 para. 1 lit. f. DSGVO, whereby the data subjects include contractual partners, interested parties, customers, visitors and users of our online offer.
The analyzes are carried out for the purpose of business analysis, marketing and market research. In doing so, we can provide the profiles of the registered users with information, e.g. take into account their services. The analyzes serve us to increase the user-friendliness, the optimization of our offer and the business economy. The analyzes are for us alone and will not be disclosed externally unless they are anonymous, aggregated value analyzes.
If these analyzes or profiles are personal, they will be deleted or anonymised upon termination of the users, otherwise after two years from the conclusion of the contract. Incidentally, the overall business analyzes and general trend provisions are created anonymously if possible.
We process the applicant data only for the purpose and in the context of the application process in accordance with the legal requirements. The processing of the applicant data takes place in order to fulfill our (pre-) contractual obligations in the context of the application process within the meaning of Art. 6 para. 1 lit. b. DSGVO Art. 6 para. 1 lit. f. DSGVO if the data processing is e.g. is required for us in the context of legal proceedings (in Germany additionally § 26 BDSG applies).
The application process requires applicants to provide us with the applicant data. The necessary applicant data are, as far as we offer an online form marked, otherwise result from the job descriptions and basically include the information on the person, postal and contact addresses and the documents belonging to the application, such as cover letter, CV and the certificates. In addition, applicants can voluntarily provide us with additional information.
Insofar as special categories of personal data within the meaning of Art. 9 (1) GDPR are voluntarily communicated within the framework of the application procedure, their processing is additionally carried out in accordance with Art. 9 (2) lit. b DSGVO (e.g., health data such as disability or ethnic origin). Insofar as special categories of personal data within the meaning of Art. 9 (1) GDPR are requested from applicants in the context of the application process, their processing is additionally carried out in accordance with Art. 9 para. 2 lit. a GDPR (for example health data, if necessary for the profession).
If provided, applicants can submit their applications via our online form on our website. The data will be encrypted and transmitted to us according to the state of the art.
Furthermore, applicants can send us their applications via e-mail. However, please note that e-mails are generally not sent encrypted and that applicants themselves must provide encryption. We can therefore take no responsibility for the transmission of the application between the sender and the reception on our server and therefore recommend rather to use an online form or the postal delivery. Because instead of applying via the online form and e-mail, applicants still have the opportunity to send us the application by post.
The data provided by the applicants may be further processed by us in the event of a successful application for employment purposes. Otherwise, if the application for a job offer is not successful, the applicants' data will be deleted. Applicants' data will also be deleted if an application is withdrawn, which the applicants are entitled to do at any time.
The cancellation is subject to a legitimate withdrawal of the candidates, after the expiration of a period of six months, so that we can answer any follow-up questions to the application and meet our proof obligations under the Equal Treatment Act. Invoices for any reimbursement of travel expenses are archived in accordance with tax regulations.
As part of the application, we offer applicants the opportunity to work in our "Talent Pool" for a period of two years on the basis of a consent in accordance with Art. 6 para. 1 lit. a. and Art. 7 GDPR.
The application documents in the Talent Pool are processed solely as part of future job advertisements and job search and will be destroyed at the latest after the deadline. Applicants are informed that their consent to be included in the Talent Pool is voluntary, has no influence on the current application process, and that they may revoke this consent at any time in the future and declare an objection within the meaning of Art. 21 GDPR.
Users can create a user account. As part of the registration, the required mandatory information is communicated to the users and based on Art. 6 para. 1 lit. b GDPR processed for purposes of providing the user account. The processed data include in particular the login information (name, password and an e-mail address). The data entered during registration will be used for the purpose of using the user account and its purpose.
Users may have access to information relevant to their user account, e.g. technical changes, be informed by e-mail. If users have terminated their user account, their data will be deleted with respect to the user account, subject to a statutory retention requirement. It is the responsibility of the users to secure their data upon termination prior to the end of the contract. We are entitled to irretrievably delete all user data stored during the term of the contract.
As part of the use of our registration and registration functions and the use of the user account, we store the IP address and the time of each user action. The storage is based on our legitimate interests, as well as the user's protection against misuse and other unauthorized use. A transfer of these data to third parties does not take place, unless it is necessary for the pursuit of our claims or there is a legal obligation in accordance with. Art. 6 para. 1 lit. c. GDPR. The IP addresses will be anonymized or deleted after 7 days at the latest.
When contacting us (for example, by contact form, e-mail, telephone or via social media), the information of the user to process the contact request and their processing acc. Art. 6 para. 1 lit. b. (in the context of contractual / pre-contractual relationships), Art. 6 para. 1 lit. f. (other requests) GDPR processed. User information can be stored in a Customer Relationship Management System ("CRM System") or comparable request organization.
We delete the requests, if they are no longer required. We check the requirement every two years, furthermore, the legal archiving obligations apply.
With the following information we inform you about the content of our newsletter as well as the registration, shipping and statistical evaluation procedures as well as your right of objection. By subscribing to our newsletter, you agree to the receipt and the procedures described.
Content of the newsletter: We send newsletters, e-mails and other electronic notifications with advertising information (hereinafter "newsletter") only with the consent of the recipient or a legal permission. Insofar as the content of a newsletter is concretely described in the context of an application for the newsletter, it is decisive for the consent of the user. Incidentally, our newsletter contains information about our services and us.
Double opt-in and logging: Registration for our newsletter is done in a so-called double opt-in procedure. That After registration, you will receive an e-mail asking you to confirm your registration. This confirmation is necessary so that nobody can register with external e-mail addresses. Registration for the newsletter will be logged in order to prove the registration process according to the legal requirements. This includes the storage of the logon and the confirmation time, as well as the IP address. Likewise, changes to your data stored with the shipping service provider will be logged.
Credentials: To subscribe to the newsletter, it is sufficient to provide your e-mail address. Optionally, we ask you to give a name in the newsletter for personal address.
The dispatch of the newsletter and the related performance measurement are based on the consent of the recipient acc. Art. 6 para. 1 lit. a, Art. 7 GDPR i.V.m § 7 Abs. 2 No. 3 UWG or if consent is not required, based on our legitimate interests in the direct marketing acc. Art. 6 para. 1 lt. F. GDPRi.V.m. § 7 Abs. 3 UWG.
The logging of the registration process is based on our legitimate interests in accordance with. Art. 6 para. 1 lit. f GDPR. We are interested in using a user-friendly and secure newsletter system that serves our business interests as well as meeting the expectations of users and allows us to provide consent.
Termination / Withdrawal - You can terminate the receipt of our newsletter at any time, ie. Revoke your consent. A link to cancel the newsletter can be found at the end of each newsletter. We may save the submitted email addresses for up to three years based on our legitimate interests before we delete them to provide prior consent. The processing of this data is limited to the purpose of a possible defense against claims. An individual request for cancellation is possible at any time, provided that at the same time the former existence of a consent is confirmed.
Newsletter - Mailchimp
The shipping service provider may retrieve the data of the recipients in pseudonymous form, i. without assignment to a user, to optimize or improve their own services, e.g. for the technical optimization of shipping and the presentation of newsletters or for statistical purposes. However, the shipping service provider does not use the data of our newsletter recipients to address them themselves or to pass the data on to third parties.
Newsletter - Success Measurement
The newsletters contain a so-called "web beacon", i. a pixel-sized file that is retrieved from the server when opening the newsletter from our server, or if we use a shipping service provider. In the course of this call, technical information, such as information about the browser and your system, as well as your IP address and time of the retrieval are collected.
This information is used to improve the technical performance of services based on their specifications or audience and their reading habits, based on their locations (which can be determined using the IP address) or access times. The statistical surveys also include determining whether the newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to the individual newsletter recipients. However, it is neither our intention nor, if used, that of the shipping service provider to observe individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.
A separate revocation of the performance measurement is unfortunately not possible, in this case, the entire newsletter subscription must be terminated.
The newsletter of F.H. Papenmeier GmbH & Co. KG contain so-called counting pixels. A counting pixel is a miniature graphic that is embedded in those emails that are sent in HTML format to enable log file recording and log file analysis. This allows a statistical evaluation of the success or failure of online marketing campaigns. Based on the embedded pixel, the F.H. Papenmeier GmbH & Co. KG recognize whether and when an e-mail was opened by a data subject and which links in the e-mail were accessed by the data subject.
Such personal data collected via the counting pixels contained in the newsletters will be stored and evaluated by the controller in order to optimize the delivery of the newsletter and to better adapt the content of future newsletters to the interests of the data subject. This personal data will not be disclosed to third parties. Affected persons are at any time entitled to revoke the separate declaration of consent issued via the double-opt-in procedure. After revocation, this personal data will be deleted by the controller. A deregistration from the receipt of the newsletter indicates the F.H. Papenmeier GmbH & Co. KG automatically as revocation.
Hosting and e-mailing
The hosting services we use are designed to provide the following services: infrastructure and platform services, computing capacity, storage and database services, e-mailing, security, and technical maintenance services we use to operate this online service.
Here we, or our hosting provider, process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, interested parties and visitors to this online offer on the basis of our legitimate interests in an efficient and secure provision of this online offer acc. Art. 6 para. 1 lit. f GDPR i.V.m. Art. 28 GDPR (conclusion of contract processing contract).
Collection of access data and log files
We, or our hosting provider, collects on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f. GDPR Data on every access to the server on which this service is located (so-called server log files). The access data includes the name of the retrieved web page, file, date and time of retrieval, amount of data transferred, notification of successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider.
Logfile information is stored for security reasons (for example, to investigate abusive or fraudulent activities) for a maximum of 7 days and then deleted. Data whose further retention is required for evidential purposes are excluded from the erasure until the final clarification of the incident.
Google is certified under the Privacy Shield Agreement, which provides a guarantee to comply with European privacy legislation (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
Google will use this information on our behalf to evaluate the use of our online offer by users, to compile reports on the activities within this online offering and to provide us with further services related to the use of this online offer and the internet usage. In this case, pseudonymous user profiles of the processed data can be created.
We only use Google Analytics with activated IP anonymization. This means that the IP address of the users is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there.
The IP address submitted by the user's browser will not be merged with other data provided by Google. Users can prevent the storage of cookies by setting their browser software accordingly; Users may also prevent the collection by Google of the data generated by the cookie and related to their use of the online offer as well as the processing of such data by Google by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=en.
The personal data of users will be deleted or anonymized after 14 months.
Google AdWords and conversion measurement
We use the services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 on the basis of our legitimate interests (ie interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 (1) lit. GDPR) , Ireland, ("Google").
Google is certified under the Privacy Shield Agreement, which provides a guarantee to comply with European privacy legislation (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
We use Google's online marketing method "AdWords" to place ads on the Google advertising network (e.g., in search results, in videos, on websites, etc.) to show them to users who have a suspected interest in the ads. This allows us to better target advertisements for and within our online offering so that we only present ads to users that potentially match their interests. If a user e.g. Showing ads for products he was looking for on other online offers is called remarketing. For these purposes, upon access to our and other websites where the Google Advertising Network is active, Google will immediately execute a code from Google and become so-called (re) marketing tags (invisible graphics or code, also as " Web beacons ") incorporated into the website. With their help, the user is provided with an individual cookie on the device. a small file is saved (instead of cookies, comparable technologies can be used). In this file is noted which web pages the user visited, for what content he is interested and what offers the user has clicked, as well as technical information about the browser and operating system, referring web pages, visit time and other information on the use of the online offer.
Furthermore, we receive an individual "conversion cookie". The information obtained through the cookie is used by Google to generate conversion statistics for us. However, we only hear about the anonymous total number of users who clicked on our ad and were redirected to a conversion tracking tag page. However, we do not receive information that personally identifies users.
The data of the users are pseudonym processed in the context of the Google advertising network. That Google stores and processes e.g. not the name or e-mail address of the users, but processes the relevant data cookie-related within pseudonymous user profiles. That from the perspective of Google, the ads are not managed and displayed to a specifically identified person, but to the cookie owner, regardless of who that cookie owner is. This does not apply if a user has expressly allowed Google to process the data without this pseudonymization. The information collected about users is transmitted to Google and stored on Google's servers in the United States.
Online presence in social media
We maintain online presence within social networks and platforms in order to communicate with customers, prospects and users active there and to inform them about our services.
We point out that data of the users outside the area of the European Union can be processed. This may result in risks to users because, e.g. the enforcement of user rights could be made more difficult. As for US providers certified under the Privacy Shield, we point out that they are committed to upholding the EU's privacy standards.
Furthermore, the data of the users are usually processed for market research and advertising purposes. Thus, e.g. user profiles are created from the user behavior and the resulting interests of the users. The usage profiles may in turn be used to e.g. Place advertisements inside and outside the platforms that are allegedly in line with users' interests. For these purposes, cookies are usually stored on the computers of the users, in which the user behavior and the interests of the users are stored. Furthermore, in the usage profiles, data can also be stored independently of the devices used by the users (in particular if the users are members of the respective platforms and logged in to them).
The processing of personal data of users is based on our legitimate interests in an effective information of users and communication with users in accordance with. Art. 6 para. 1 lit. f. GDPR. If the users are asked by the respective providers of the platforms for a consent to the above-described data processing, the legal basis of the processing is Art. 6 para. 1 lit. a., Art. 7 GDPR.
For a detailed description of the respective processing and the possibilities of contradiction (opt-out), we refer to the following linked information of the provider.
Also in the case of requests for information and the assertion of user rights, we point out that these can be claimed most effectively from the providers. Only the providers have access to the data of the users and can directly take appropriate measures and provide information. If you still need help, then you can contact us.
Integration of services and contents of third parties
Based on our legitimate interests (ie interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 (1) lit. GDPR), we make use of content or services offered by third-party providers in order to provide their content and services Services, such as Include videos or fonts (collectively referred to as "content").
This always presupposes that the third-party providers of this content perceive the IP address of the users, since they could not send the content to their browser without the IP address. The IP address is therefore required for the presentation of this content. We endeavor to use only content whose respective providers use the IP address only for the delivery of the content. Third parties may also use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information, such as visitor traffic, on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may include, but is not limited to, technical information about the browser and operating system, referring web pages, time of visit, and other information regarding the use of our online offer.
Use of Facebook social plugins
On the basis of our legitimate interests (ie interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 (1) lit. GDPR) we use social plugins ("plugins") of the social network facebook.com, which operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland ("Facebook").
For this, e.g. Content such as pictures, videos or text and buttons belong, with which users can share contents of this on-line offer within Facebook. The list and appearance of Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins/.
Facebook is certified under the Privacy Shield Agreement, which provides a guarantee to comply with European privacy legislation (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).
When a user invokes a feature of this online offering that includes such a plugin, their device establishes a direct connection to the Facebook servers. The content of the plugin is transmitted by Facebook directly to the device of the user and incorporated by him into the online offer. In the process, user profiles of the processed data can be created. We therefore have no influence on the extent of the data that Facebook collects with the help of this plugin and therefore informs users according to our level of knowledge.
By integrating the plugins, Facebook receives the information that a user has accessed the corresponding page of the online offer. If the user is logged in to Facebook, Facebook can assign the visit to his Facebook account. If users interact with the plugins, for example, press the Like button or leave a comment, the information is transmitted from your device directly to Facebook and stored there. If a user is not a member of Facebook, there is still the possibility that Facebook will find out and save their IP address. According to Facebook, only an anonymous IP address is stored in Germany.
If a user is a Facebook member and does not want Facebook to collect data about him via this online offer and link it to his member data stored on Facebook, he must log out of Facebook and delete his cookies before using our online offer. Other settings and inconsistencies regarding the use of data for promotional purposes are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US-American site http://www.aboutads.info/choices/ or the EU page http://www.youronlinechoices.com/. The settings are platform independent, i. they are adopted for all devices, such as desktop computers or mobile devices.
Legal basis of processing
Art. 6 I lit. a GDPR serves our company as the legal basis for processing operations in which we obtain consent for a particular processing purpose. If the processing of personal data is necessary to fulfill a contract of which the data subject is a party, as is the case, for example, in processing operations necessary for the supply of goods or the provision of any other service or consideration, processing shall be based on Art. 6 I lit. b GDPR. The same applies to processing operations that are necessary to carry out pre-contractual measures, for example in the case of inquiries about our products or services. If our company is subject to a legal obligation which requires the processing of personal data, such as the fulfillment of tax obligations, the processing is based on Art. 6 I lit. c GDPR. In rare cases, the processing of personal data may be required to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor to our premises were injured and his or her name, age, health insurance or other vital information would have to be passed on to a doctor, hospital or other third party. Then the processing would be based on Art. 6 I lit. d GDPR are based. Ultimately, processing operations could be based on Art. 6 I lit. f GDPR are based. Processing operations that are not covered by any of the above legal bases are based on this legal basis if processing is necessary to safeguard the legitimate interests of our company or a third party, unless the interests, fundamental rights and fundamental freedoms of the person concerned prevail. Such processing operations are particularly permitted because they have been specifically mentioned by the European legislator. In that regard, it considered that a legitimate interest could be assumed if the data subject is a customer of the controller (recital 47, second sentence, GDPR).
Qualified interests in the processing being pursued by the controller or a third party
Is the processing of personal data based on Article 6 I lit. f GDPR is our legitimate interest in conducting our business for the benefit of all of our employees and our shareholders.
Duration for which the personal data is stored
The criterion for the duration of the storage of personal data is the respective statutory retention period. After the deadline, the corresponding data will be routinely deleted, if they are no longer required to fulfill the contract or to initiate a contract.
Legal or contractual provisions for the provision of personal data; Necessity for the conclusion of the contract; Obligation of the data subject to provide the personal data; possible consequences of non-provision.
We clarify that the provision of personal information is in part required by law (such as tax regulations) or may result from contractual arrangements (such as details of the contractor). Occasionally it may be necessary for a contract to be concluded that an affected person provides us with personal data that must subsequently be processed by us. For example, the data subject is required to provide us with personal information when our company concludes a contract with her. Failure to provide the personal data would mean that the contract with the person concerned could not be closed. Prior to any personal data being provided by the person concerned, the person concerned must contact one of our employees. Our employee will inform the individual on a case-by-case basis whether the provision of the personal data is required by law or contract or required for the conclusion of the contract, whether there is an obligation to provide the personal data, and what would have resulted from the failure to provide the personal data.
Existence of automated decision-making
As a responsible company, we refrain from automatic decision-making or profiling.